Sceawere
Vulnerability Detail
CVE-2026-28174UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WP Event Solution Sensitive Data Exposure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 7h ago
- Vendor
- Arraytics
- Product
- WP Event SOlution
- Attack Type
- CWE-201 Insertion of Sensitive Information Into Sent Data
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Customer Sensitive Data Exposure in WP Event SOlution <= 4.1.18 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-08-13T14:16:59.403Z",
"pubdate": "2026-08-13T14:16:59.403Z",
"executiveSummary": "A sensitive data exposure vulnerability has been identified in the WP Event Solution plugin, affecting all versions up to and including 4.1.18. This security flaw allows unauthorized third parties to access confidential information stored or processed by the affected component. The vulnerability poses significant risk implications regarding data confidentiality, potentially exposing sensitive user details or internal system configurations to malicious actors. Attackers capable of exploiting this vulnerability require network access to the target system, though explicit authentication or privilege requirements are dictated by the underlying exposure mechanism. Successful exploitation leads directly to the unauthorized retrieval of sensitive data without requiring sophisticated interaction or elevated access privileges, increasing the overall risk posture for installations running vulnerable iterations of the product.",
"technicalDetails": "The vulnerability resides within the WP Event Solution plugin codebase for versions <= 4.1.18, specifically concerning inadequate access controls and improper handling of sensitive information requests. The root cause stems from the failure of the application logic to adequately sanitize, restrict, or authenticate incoming requests targeting endpoints or resources that handle sensitive data. From a network exposure perspective, the vulnerable component is accessible over standard web protocols, exposing the endpoint to remote attackers via crafted HTTP requests. Exploitation occurs when an unauthenticated or low-privileged attacker transmits specifically crafted requests to the vulnerable functionality within the plugin. Upon receiving the request, the affected component fails to validate whether the requester possesses the necessary authorization to view the requested data. Consequently, the application processes the request and returns the confidential information within the HTTP response payload. This post-exploitation impact allows malicious actors to harvest sensitive data directly from the server response, facilitating further reconnaissance or targeted attacks against the hosting environment. The absence of strict input validation and access control enforcement mechanisms forms the primary vector enabling this data leakage."
}